| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site. |
| The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete/mark as read/mark as unread notifications of other users. |
| Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. |
| Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. |
| The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. |
| Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. |
| Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. |
| Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. |
| Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. |
| Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions. |
| Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions. |
| Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions. |
| Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. |
| Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions. |
| import_contacts Path Traversal in Groundhogg <= 4.7.1 versions. |
| Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions. |
| Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions. |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965. |